CRITICAL · 10.0

CVE-2021-27446

The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.

Vulnerability Description

The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.

CVSS Score

10.0

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
WeintekCmt-Svr-100 Firmware< 20210305
WeintekCmt-Svr-100-
WeintekCmt-Svr-102 Firmware< 20210305
WeintekCmt-Svr-102-
WeintekCmt-Svr-200 Firmware< 20210305
WeintekCmt-Svr-200-
WeintekCmt-Svr-202 Firmware< 20210305
WeintekCmt-Svr-202-
WeintekCmt-G01 Firmware< 20210209
WeintekCmt-G01-
WeintekCmt-G02 Firmware< 20210209
WeintekCmt-G02-
WeintekCmt-G03 Firmware< 20210222
WeintekCmt-G03-
WeintekCmt-G04 Firmware< 20210222
WeintekCmt-G04-
WeintekCmt3071 Firmware< 20210218
WeintekCmt3071-
WeintekCmt3072 Firmware< 20210218
WeintekCmt3072-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-27446?

CVE-2021-27446 is a vulnerability with a CVSS score of 10.0 (CRITICAL). The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.

How severe is CVE-2021-27446?

CVE-2021-27446 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-27446?

Check the references section above for vendor advisories and patch information. Affected products include: Weintek Cmt-Svr-100 Firmware, Weintek Cmt-Svr-100, Weintek Cmt-Svr-102 Firmware, Weintek Cmt-Svr-102, Weintek Cmt-Svr-200 Firmware.